IP Library Granted Patent US 12,437,046
Granted Patent B2
US 12,437,046 · App. 18/063,264 · Granted Oct 7, 2025

Method, apparatus, and recording medium for performing authentication

Inventors: Oleksii Piskun (Kyiv, UA); Vitalii Petrychenko (Kyiv, UA); Mykola Alieksieiev (Kyiv, UA); Oleg Kopysov (Kyiv, UA); Stanislav Pedan (Kyiv, UA)
Assignee: Samsung Electronics Co., Ltd.
G06F21/32G06F21/45G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,437,046
App. No.
18/063,264
Granted
Oct 7, 2025
Kind
B2
Abstract

A method of performing authentication by an electronic apparatus and an electronic apparatus for performing authentication are provided. The electronic apparatus receives an access request to an application executed on the electronic apparatus, obtain any one of public helper data and private helper data, which are used for user authentication, based on the access requested application, obtain an encryption key from user's biometric information received according to the access request, based on the public helper data or the private helper data by using a fuzzy extractor, and perform user authentication for accessing the application, based on the obtained encryption key.

Claims (66)

1. A method of performing authentication by an electronic apparatus, the method comprising:

receiving an access request to an application executed on the electronic apparatus and biometric information of a user of the electronic apparatus;

identifying an authentication level required in the application;

based on a result of comparing the authentication level with a preset value, obtaining either public helper data stored in a server or private helper data stored in the electronic apparatus as helper data used for user authentication;

obtaining an encryption key based on the biometric information of the user and either the public helper data or the private helper data by using a fuzzy extractor; and

performing user authentication for accessing the application, based on the encryption key,

wherein the public helper data is used to generate the encryption key for access to an application that requires security greater than or equal to a reference value, and the private helper data is used to generate the encryption key for access to an application that requires security lower than the reference value.

2. The method of claim 1 , further comprising:

requesting user information registration via a user information registration request; and

generating the encryption key corresponding to the biometric information of the user, the public helper data, and the private helper data, by using the fuzzy extractor, from the biometric information of the user obtained according to the user information registration request,

wherein the public helper data is transmitted to a server, the private helper data is stored in the electronic apparatus, and the encryption key corresponding to the biometric information of the user is deleted.

3. The method of claim 1 , wherein the obtaining of the private helper data comprises:

based on the authentication level being less than the preset value, obtaining private helper data corresponding to the authentication level from at least one piece of the private helper data stored in the electronic apparatus.

4. The method of claim 3 , wherein the obtaining of the encryption key comprises:

identifying whether a degree of matching between a hash value corresponding to the biometric information of the user and a hash value corresponding to the private helper data is greater than or equal to a first threshold value; and

obtaining the encryption key by using the biometric information of the user, the private helper data, and a Rep function, based on whether the degree of matching is greater than or equal to the first threshold value.

5. The method of claim 3 , wherein the obtaining of the private helper data comprises:

based on the authentication level being greater than or equal to the preset value, requesting public helper data from a server; and

receiving the public helper data from the server, based on the requesting.

6. The method of claim 5 , wherein the obtaining of the encryption key comprises:

identifying whether a degree of matching between a hash value corresponding to the biometric information of the user and a hash value corresponding to the public helper data is greater than or equal to a second threshold value; and

obtaining the encryption key by using the biometric information of the user, the public helper data, and a Rep function, based on whether the degree of matching is greater than or equal to the second threshold value.

7. The method of claim 1 , further comprising:

receiving a recovery request of the private helper data;

receiving second biometric information;

identifying whether a degree of matching between a hash value corresponding to the second biometric information and a hash value corresponding to the public helper data is greater than or equal to a third threshold value, based on the public helper data received from a server; and

generating the encryption key and the private helper data by using the second biometric information, the public helper data, and a Rep function, based on whether the degree of matching is greater than or equal to the third threshold value.

8. An electronic apparatus for performing authentication, the electronic apparatus comprising:

a communication unit;

memory storing one or more instructions; and

at least one processor configured to execute the one or more instructions stored in the memory,

wherein the at least one processor is further configured to:

receive an access request to an application executed on the electronic apparatus and biometric information of a user of the electronic apparatus,

identify an authentication level required in the application,

based on a result of comparing the authentication level with a preset value, obtain either public helper data stored in a server or private helper data stored in the electronic apparatus as helper data used for user authentication,

obtain an encryption key based on the biometric information of the user and either the public helper data or the private helper data by using a fuzzy extractor, and

perform user authentication for accessing the application, based on the encryption key, and

wherein the public helper data is used to generate the encryption key for access to an application that requires security greater than or equal to a reference value, and the private helper data is used to generate the encryption key for access to an application that requires security lower than the reference value.

9. The electronic apparatus of claim 8 ,

wherein the at least one processor is further configured to:

request user information registration via a user information registration request; and

generate the encryption key corresponding to the biometric information of the user, the public helper data, and the private helper data, by using the fuzzy extractor, from biometric information of the user obtained according to the user information registration request, and

wherein the public helper data is transmitted to a server, the private helper data is stored in the electronic apparatus, and the encryption key corresponding to the biometric information of the user is deleted.

10. The electronic apparatus of claim 8 , wherein the at least one processor is further configured to:

based on the authentication level being less than the preset value, obtain private helper data corresponding to the authentication level, from at least one piece of the private helper data stored in the electronic apparatus.

11. The electronic apparatus of claim 10 , wherein the at least one processor is further configured to:

identify whether a degree of matching between a hash value corresponding to the biometric information of the user and a hash value corresponding to the private helper data is greater than or equal to a first threshold value; and

obtain the encryption key by using the biometric information of the user, the private helper data, and a Rep function, based on whether the degree of matching is greater than or equal to the first threshold value.

12. The electronic apparatus of claim 10 , wherein the at least one processor is further configured to:

when the authentication level is greater than or equal to the preset value, control the communication unit to request public helper data from a server; and

control the communication unit to receive the public helper data from the server, based on the requesting.

13. The electronic apparatus of claim 12 , wherein the at least one processor is further configured to:

identify whether a degree of matching between a hash value corresponding to the biometric information of the user and a hash value corresponding to the public helper data is greater than or equal to a second threshold value; and

obtain the encryption key by using the biometric information of the user, the public helper data, and a Rep function, based on whether the degree of matching is greater than or equal to the second threshold value.

14. The electronic apparatus of claim 8 , wherein the at least one processor is further configured to:

receive a recovery request of the private helper data;

receive second biometric information;

identify whether a degree of matching between a hash value corresponding to the second biometric information and a hash value corresponding to the public helper data is greater than or equal to a third threshold value, based on the public helper data received from a server; and

generate the encryption key and the private helper data by using the second biometric information, the public helper data, and a Rep function, based on whether the degree of matching is greater than or equal to the third threshold value.

15. A non-transitory computer-readable recording medium having stored therein one or more instructions, which causes an electronic apparatus to:

receive an access request to an application executed on the electronic apparatus and biometric information of a user of the electronic apparatus;

identify an authentication level required in the application;

based on a result of comparing the authentication level with a preset value, obtain either public helper data stored in a server or private helper data stored in the electronic apparatus as helper data used for user authentication;

obtain an encryption key based on the biometric information of the user and either the public helper data or the private helper data by using a fuzzy extractor; and

perform user authentication for accessing the application, based on the encryption key,

wherein the public helper data is used to generate the encryption key for access to an application that requires security greater than or equal to a reference value, and the private helper data is used to generate the encryption key for access to an application that requires security lower than the reference value.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2022
From: PISKUN, OLEKSII; PETRYCHENKO, VITALII; ALIEKSIEIEV, MYKOLA; KOPYSOV, OLEG; PEDAN, STANISLAV
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 062026/0952 →
Priority Claims (1)
KR 10-2020-0069852 · Jun 9, 2020 · national
Continuity (2)
Continuation PCTKR2020008507 · Jun 30, 2020
Related Publication 20230100037A1 · Mar 30, 2023
References Cited (29)
US 8879728B2 · MacMillan · 2014 [cited by examiner]
US 9031231B2 · Asim et al. · 2015 [cited by applicant]
US 9384338B2 · Kevenaar et al. · 2016 [cited by applicant]
US 9614843B2 · Jia et al. · 2017 [cited by applicant]
US 9800562B2 · Lalwani et al. · 2017 [cited by applicant]
US 10778423B2 · Cho et al. · 2020 [cited by applicant]
US 11223478B2 · Eldefrawy et al. · 2022 [cited by applicant]
US 11777736B2 · Blackhurst · 2023 [cited by examiner]
US 20140325230A1 · Sy · 2014 [cited by examiner]
US 20150095654A1 · Li · 2015 [cited by examiner]
US 20160100314A1 · Chung · 2016 [cited by examiner]
US 20170149572A1 · Wallrabenstein · 2017 [cited by examiner]
US 20170185761A1 · Stanwood · 2017 [cited by examiner]
US 20190020472A1 · Cho et al. · 2019 [cited by applicant]
US 20190312731A1 · Eldefrawy · 2019 [cited by examiner]
US 20200145206A1 · Cho et al. · 2020 [cited by applicant]
US 20200296093A1 · Hoyos · 2020 [cited by examiner]
EP 3374913A1 · 2018 [cited by applicant]
JP 2019161405A · 2019 [cited by applicant]
KR 101792220B1 · 2017 [cited by applicant]
KR 1020190070472A · 2019 [cited by applicant]
KR 102035249B1 · 2019 [cited by applicant]
KR 1020190129417A · 2019 [cited by applicant]
WO 2015047385A1 · 2015 [cited by applicant]
Chang D, Garg S, Hasan M, Mishra S. Cancelable multi-biometric approach using fuzzy extractor and novel bit-wise encryption. IEEE Transactions on Information Forensics and Security. Mar. 25, 2020;15:3152-67. (Year: 2020… [cited by examiner]
NPL Search Terms (Year: 2025). [cited by examiner]
Yining Liu et al., A secure data backup scheme using multifactor authentication, IET Information Security, ISSN 1751-8709, Nov. 2016. [cited by applicant]
International Search Report dated Feb. 26, 2021, issued in International Application No. PCT/KR2020/008507. [cited by applicant]
Korean Office Action dated Sep. 1, 2024, issued in Korean Patent Application No. 10-2020-0069852. [cited by applicant]